Uninstall list: I do not see anything that jumps out at me as malware, but I just do not know all of those programs. I suggest you take a loog at the items and if there are programs you know you no longer use, get rid of them. I wonder why this program shows it is installed twice?
Windows Media Player 11
Windows Media Player 11


SmitFraudFix v2.132
C:\WINDOWS\ads.js FOUND !

Follow these instructions:
Clean:
Reboot your computer in Safe Mode (before the Windows icon appears, tap the F8 key continually)
Double-click SmitfraudFix.exe
Select 2 and hit Enter to delete infect files.
You will be prompted: Do you want to clean the registry ? answer Y (yes) and hit Enter in order to remove the Desktop background and clean registry keys associated with the infection.
The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found): Replace infected file ? answer Y (yes) and hit Enter to restore a clean file.
A reboot may be needed to finish the cleaning process. The report can be found at the root of the system drive, usually at C:\rapport.txt

Optional:
To restore Trusted and Restricted site zone, select 3 and hit Enter.
You will be prompted: Restore Trusted Zone ? answer Y (yes) and hit Enter to delete trusted zone.
Note, if you use SpywareBlaster and/or IE-SPYAD, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE-SPYAD, run the batch file and reinstall the protection.


Logfile of HijackThis v1.99.1 Scan saved at 11:20:53 AM, on 1/16/2007This item is still in the HJT log? Either you missed it when you used HJT, TeaTimer was not turned off? Or you did not delete the filder? It is LOP/C2 Media and it must be removed before your computer is clean.

Turn off TeaTimer using the instructions I posted before (if you have to uninstall Spybot until it is removed and reinstall it later.
Use HJT to remove the line from the HJT log (make sure you have all windows and all other programs closed (nothing should be running but HJT when you use it)
Navigate right to the folder before doing anything else and delete the folder highlited in red.

O4 - HKCU\..\Run: [loadfork] C:\DOCUME~1\KENABA~1\APPLIC~1\CASHDA~1\BOLT WARN AIM.exe <<< delete that folder
Restart and post the C:\rapport.txt from Smitfraudfix and a HJT log with the LOP item removed.

Once that item is gone then do this:
System Restore does not know the good files from the bad. In case bad stuff has gotten into your System Restore files, follow the instructions in this link to get clean System Restore files. Turn it off, reboot then turn it back on:
http://service1.symantec.com/SUPPORT...rc=sec_doc_nam

AVG Anti-Spyware is a good program but it does use some resources. Once the trial is over you can update and use the scanner for as long as you wish, but unless you purchase it you should turn it off completely so it does not run unless you start it manually.

Here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online:
http://forums.spybot.info/showthread.php?t=279
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html
http://cybercoyote.org/security/not-admin.shtml

Thanks...pskelley
Safer Networking Forums
http://www.spybot.info/en/donate/index.html
If you are reading this information...thank a teacher,
If you are reading it in English...thank a soldier.